Suse Linux Enterprise Live Patching
Vendor:
First CVE: Apr 27, 2016 · Active for 10 years
22
Total CVEs
More Total CVEs than 95% of tracked products
22.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 19% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Suse Linux Enterprise Live Patching over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2016
10 years ago
Most Recent CVE
Jul 3, 2016
3,677 days ago
CVE Severity & Scoring
Suse Linux Enterprise Live Patching22 CVEs
73%
23%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local10 (45.5%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical12 (54.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None22 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (31.8%)
High0 (0.0%)
None15 (68.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4997HIGH The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or | Jul 3, 2016 | 7.8 | 47 | NO | YES |
CVE-2016-3672HIGH The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local user | Apr 27, 2016 | 7.8 | 36 | NO | YES |
CVE-2016-3134HIGH The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap me | Apr 27, 2016 | 8.4 | 35 | NO | YES |
CVE-2016-1583HIGH The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory con | Jun 27, 2016 | 7.8 | 30 | NO | YES |
CVE-2016-3140MEDIUM The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointe | May 2, 2016 | 4.6 | 28 | NO | YES |
CVE-2016-2184MEDIUM The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of | Apr 27, 2016 | 4.6 | 28 | NO | YES |
CVE-2016-3136MEDIUM The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointe | May 2, 2016 | 4.6 | 27 | NO | YES |
CVE-2016-2188MEDIUM The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer deref | May 2, 2016 | 4.6 | 26 | NO | YES |
CVE-2016-3139MEDIUM The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer derefe | Apr 27, 2016 | 4.6 | 26 | NO | YES |
CVE-2016-4805HIGH Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, | May 23, 2016 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
45.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Suse Linux Enterprise Live Patching
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 12.0 | 22 | 5.6 | 1.3% | 0 | 10 |